MPE+ is a completely standalone product and the physical extracted files can be viewed from within the product. I have not needed to use FTK to complete a job, but it is handy to have as a resource!
Some of the features I enjoy in this product:
Physical Extraction (my main product for physical)
Ability to import images (E01, Yaffs, DD, Cellbrite etc) for analysis or verification
Timeline Visualisation/Social Analysis
Mount image to run malware analysis
Built in parsers for Android, iOS, IPD & Itunes backup.
Built in SQLite browser & Application one click support
I am hopeful that AccessData will incorporate their Cerberus Malware tools into this program in the future for live malware analysis.
MPE+ has come a long way in the last 2 years and I am personally pleased with the updates so far. The product is not perfect and I cannot answer to the lack of language support but when I have needed the support it has always been there. With the imminent merger of the e-discovery and investigation products in the next few months, AD will make it seamless to analyse AD1 images in all the products.
The other tools I use for mobile are Blacklight and Oxygen Analyst.
Disclaimer: I have not used UFED.
↧